KOMPROGO

S0156

Malware.View on attack.mitre.org

About this malware

KOMPROGO is a signature backdoor used by APT32 that is capable of process, file, and registry management.

Techniques used3

Procedure examples3

TechniqueProcedure example
T1047
Windows Management Instrumentation

KOMPROGO is capable of running WMI queries.

T1059.003
Windows Command Shell

KOMPROGO is capable of creating a reverse shell.

T1082
System Information Discovery

KOMPROGO is capable of retrieving information about the infected system.

Groups that use it1

Campaigns0

None recorded.

References1

  1. FireEye APT32 May 2017 Open source
    Carr, N.. (2017, May 14). Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations. Retrieved June 18, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.